Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please upgrade to FortiOS 7.4.2 or above Please upgrade to FortiOS 7.2.7 or above Please upgrade to ForitOS 7.0.13 or above Workaround- Disable push notifications for FortiAuthenticator: For RADIUS Authentication (From FortiAuthenticator)- ## RADIUS Service > Policies > (select policy) > Authentication Factors > Advanced Options > ## Allow FortiToken Mobile push notifications (*disable)*
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50901 | An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts. |
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-424 |
|
No history.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T20:53:21.214Z
Reserved: 2023-10-25T08:43:15.290Z
Link: CVE-2023-46717
Updated: 2024-08-02T20:53:21.214Z
Status : Modified
Published: 2024-03-12T15:15:46.487
Modified: 2024-11-21T08:29:08.597
Link: CVE-2023-46717
No data.
OpenCVE Enrichment
No data.
EUVD